← Back

Cybozu

cybozu

330 CVEs • 21 products

Products (21)

Click to collapse
Toggle
Garoon
garoon
Office
office
Mailwise
mailwise
Cybozu Office
cybozu_office
Dezie
dezie
Kunai
kunai
Cybozu Live
cybozu_live
Kintone
kintone
Collaborex
collaborex
Cybozu Dezie
cybozu_dezie
Share360
share360
Share 360
share_360
Cybozu Ag
cybozu_ag
Cybozu Pocket
cybozu_pocket
Garoon 1
garoon_1
Cybozu Garoon
cybozu_garoon
Desktop
desktop

CVEs (330)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cybozu
1Remote Service Manager
Jun 17, 2026
Oct 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
1Cybozu
1Remote Service Manager
Jun 17, 2026
Oct 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site script inclusion vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to obtain the information stored in the product. This issue occurs only when using...Show more
Cross-site script inclusion vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to obtain the information stored in the product. This issue occurs only when using Mozilla Firefox.Show less
1Cybozu
1Remote Service Manager
Jun 17, 2026
Oct 13, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to upload an arbitrary file via unspecified vectors.
1Cybozu
1Remote Service Manager
Jun 17, 2026
Oct 13, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack the authentication of administrators and unintended operations may be pe...Show more
Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack the authentication of administrators and unintended operations may be performed via unspecified vectors.Show less
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper input validation vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the data of Comment and Space without the viewing privilege.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in some functions of E-mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
There is a vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.5.0, which may allow a remote authenticated attacker to delete the route information Workflow without the appropriate privilege.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Information disclosure vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the title of Bulletin without the viewing privilege.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in some functions of E-Mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote attacker to inject an arbitrary script via unspecified vectors.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in Message of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Operational restrictions bypass vulnerability in Scheduler and MultiReport of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to delete the data of Scheduler and MultiReport without the appropriate pr...Show more
Operational restrictions bypass vulnerability in Scheduler and MultiReport of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to delete the data of Scheduler and MultiReport without the appropriate privilege.Show less
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in Full Text Search of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Improper input validation vulnerability in Attaching Files of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to alter the data of Attaching Files.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Operational restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the appropriate privilege.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated to alter the data of E-mail without the appropriate privilege.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
2.7 LOW· v3
3.5 LOW· v2
Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker with an administrative privilege to alter the data of E-mail without the appropriate privilege.
1Cybozu
1Garoon
Jun 17, 2026
Aug 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper input validation vulnerability in User Profile of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of User Profile without the appropriate privilege.